서브메뉴
검색
Machine Learning Methodologies for Low-Level Hardware-Based Malware Detection
Machine Learning Methodologies for Low-Level Hardware-Based Malware Detection
상세정보
- 자료유형
- 학위논문 서양
- 최종처리일시
- 20260202105543
- ISBN
- 9798263399924
- DDC
- 621.384
- 저자명
- Chawla, Nikhil.
- 서명/저자
- Machine Learning Methodologies for Low-Level Hardware-Based Malware Detection
- 발행사항
- [Sl] : Georgia Institute of Technology, 2021
- 발행사항
- Ann Arbor : ProQuest Dissertations & Theses, 2021
- 형태사항
- 138 p
- 주기사항
- Source: Dissertations Abstracts International, Volume: 87-05, Section: B.
- 주기사항
- Advisor: Mukhopadhyay, Saibal.
- 학위논문주기
- Thesis (Ph.D.)--Georgia Institute of Technology, 2021.
- 초록/해제
- 요약Malicious software continues to be a pertinent threat to the security of critical infrastructures harboring sensitive information. The abundance in malware samples and the disclosure of newer vulnerability paths for exploitation necessitates intelligent machine learning techniques for effective and efficient malware detection and analysis. Software-based methods are suitable for in-depth forensic analysis, but their on-device implementations are slower and resource hungry. Alternatively, hardware-based approaches are emerging as an alternative approach against malware threats because of their trustworthiness, difficult evasion, and lower implementation costs. Modern processors have numerous hardware events such as power domains, voltage, frequency, accessible through software interfaces for performance monitoring and debugging. But, information leakage from these events are not explored for defenses against malware threats. This thesis demonstrates approach towards malware detection and analysis by leveraging low-level hardware signatures.The proposed research aims to develop machine learning methodology for detecting malware applications, classifying malware family and detecting shellcode exploits from low-level power signatures and electromagnetic emissions. This includes 1) developing a signature based detector by extracting features from DVFS states and using ML model to distinguish malware application from benign. 2) developing ML model operating on frequency and wavelet features to classify malware behaviors using EM emissions. 3) developing an Restricted Boltzmann Machine (RBM) model to detect anomalies in energy telemetry register values of malware infected application resulting from shellcode exploits. The evaluation of the proposed ML methodology on malware datasets indicate architectureagnostic, pervasive, platform independent detectors that distinguishes malware against benign using DVFS signatures, classifies detected malware to characteristic family using EM signatures, and detect shellcode exploits on browser applications by identifying anomalies in energy telemetry register values using energy-based RBM model.
- 일반주제명
- Telemetry
- 일반주제명
- Exploitation
- 일반주제명
- Malware
- 일반주제명
- Software upgrading
- 일반주제명
- Computer viruses
- 일반주제명
- Energy
- 일반주제명
- Governors
- 일반주제명
- Computer science
- 기본자료저록
- Dissertations Abstracts International. 87-05B.
- 전자적 위치 및 접속
- 로그인 후 원문을 볼 수 있습니다.
MARC
008260126s2021 us c eng d■001000017360534
■00520260202105543
■006m o d
■007cr#unu||||||||
■020 ▼a9798263399924
■035 ▼a(MiAaPQ)AAI32315393
■035 ▼a(MiAaPQ)GeorgiaTech66100
■040 ▼aMiAaPQ▼cMiAaPQ
■0820 ▼a621.384
■1001 ▼aChawla, Nikhil.
■24510▼aMachine Learning Methodologies for Low-Level Hardware-Based Malware Detection
■260 ▼a[Sl]▼bGeorgia Institute of Technology▼c2021
■260 1▼aAnn Arbor▼bProQuest Dissertations & Theses▼c2021
■300 ▼a138 p
■500 ▼aSource: Dissertations Abstracts International, Volume: 87-05, Section: B.
■500 ▼aAdvisor: Mukhopadhyay, Saibal.
■5021 ▼aThesis (Ph.D.)--Georgia Institute of Technology, 2021.
■520 ▼aMalicious software continues to be a pertinent threat to the security of critical infrastructures harboring sensitive information. The abundance in malware samples and the disclosure of newer vulnerability paths for exploitation necessitates intelligent machine learning techniques for effective and efficient malware detection and analysis. Software-based methods are suitable for in-depth forensic analysis, but their on-device implementations are slower and resource hungry. Alternatively, hardware-based approaches are emerging as an alternative approach against malware threats because of their trustworthiness, difficult evasion, and lower implementation costs. Modern processors have numerous hardware events such as power domains, voltage, frequency, accessible through software interfaces for performance monitoring and debugging. But, information leakage from these events are not explored for defenses against malware threats. This thesis demonstrates approach towards malware detection and analysis by leveraging low-level hardware signatures.The proposed research aims to develop machine learning methodology for detecting malware applications, classifying malware family and detecting shellcode exploits from low-level power signatures and electromagnetic emissions. This includes 1) developing a signature based detector by extracting features from DVFS states and using ML model to distinguish malware application from benign. 2) developing ML model operating on frequency and wavelet features to classify malware behaviors using EM emissions. 3) developing an Restricted Boltzmann Machine (RBM) model to detect anomalies in energy telemetry register values of malware infected application resulting from shellcode exploits. The evaluation of the proposed ML methodology on malware datasets indicate architectureagnostic, pervasive, platform independent detectors that distinguishes malware against benign using DVFS signatures, classifies detected malware to characteristic family using EM signatures, and detect shellcode exploits on browser applications by identifying anomalies in energy telemetry register values using energy-based RBM model.
■590 ▼aSchool code: 0078.
■650 4▼aTelemetry
■650 4▼aExploitation
■650 4▼aMalware
■650 4▼aSoftware upgrading
■650 4▼aComputer viruses
■650 4▼aEnergy
■650 4▼aGovernors
■650 4▼aComputer science
■690 ▼a0791
■690 ▼a0800
■690 ▼a0984
■71020▼aGeorgia Institute of Technology.
■7730 ▼tDissertations Abstracts International▼g87-05B.
■790 ▼a0078
■791 ▼aPh.D.
■792 ▼a2021
■793 ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17360534▼nKERIS▼z이 자료의 원문은 한국교육학술정보원에서 제공합니다.


